Social Engineering Attacks
Social engineering attacks are based on the exploitation of someone's personality; they could be referred to as hacking the human. There are various types of social engineering attacks. Let's look at each of them in turn, starting with phishing/spear phishing:
- Phishing: Phishing attacks are indiscriminate email attacks requesting that the recipient completes an attached form (perhaps saying that there is a problem with their bank account). Such forms ask for personal details that could later be used for identity fraud. These emails often look as though they have come from a legitimate body, so users are fooled into carrying out the instructions they contain.
- Spear Phishing is a phishing attack that targets a specific group of people.
- Prepending: An attacker will add information to a subject line of an email to make it look as if has been scanned by the mail system before it arrives. This way, the users thinks that the email is safe...